Security at TurboCart AI

Your store data is valuable. We treat it that way. Here's how we keep it safe.

Encryption in Transit & At Rest

All data transmitted between your browser and our servers uses TLS 1.3. Data stored in our databases is encrypted at rest using AES-256.

Role-Based Access Control

Internal access to production data is strictly limited. Engineers follow the principle of least privilege and require approval for any data access.

Secure Infrastructure

TurboCart AI is hosted on enterprise-grade cloud infrastructure with automatic failover, DDoS protection, and continuous uptime monitoring.

Audit Logs

All significant actions within the platform — logins, data exports, setting changes — are logged with timestamps for traceability.

Regular Security Reviews

Our codebase undergoes regular internal security reviews. We use automated dependency scanning to detect and patch known vulnerabilities.

Authentication Security

Passwords are hashed using bcrypt. We support two-factor authentication and enforce secure session management with short-lived tokens.

Your Data, Your Rights

Data Isolation

Each merchant account is isolated. Your store data is never shared with or accessible by other accounts, even within the same plan tier.

Third-Party Integrations

Integrations with Shopify, WooCommerce, and others use OAuth or official API tokens scoped to only what's necessary. We never store marketplace passwords.

Data Retention

You can delete your account and data at any time. We process deletion requests within 30 days and provide a data export before deletion if requested.

No Data Selling

We do not sell, rent, or monetize your personal or store data. It is used solely to operate and improve the TurboCart AI platform.

Found a Security Issue?

We take security disclosures seriously. If you believe you've found a vulnerability in our platform, please email us directly — do not post it publicly.

security@turbocartai.xyz